CVE-2023-45857

Aliases:GHSA-wf5p-g6vw-rhxxDEBIAN-CVE-2023-45857UBUNTU-CVE-2023-45857CGA-24xg-5hh4-whwvCGA-28jw-rr4r-fc2qCGA-2chf-qchm-ffg9CGA-2m7f-9568-cmjmCGA-2mmf-qfq4-5c65CGA-2vm6-6j8w-w5g9CGA-33rc-pf32-v554CGA-3424-27f6-qcr5CGA-34q6-9jcq-cqcxCGA-34wv-27mh-qp23CGA-36g8-xwcc-qwj2CGA-386f-qm54-xgmjCGA-3hf9-62fg-qjf4CGA-3jcq-prhm-63mwCGA-3m77-72rh-2q82CGA-3mmj-8r6x-hgcwCGA-3q4m-mwv5-cq2rCGA-3q88-gjg9-x297CGA-3q8r-h6rx-j8p5CGA-3rcf-qvvg-64pgCGA-42c9-f5w2-hhw4CGA-472v-mrq9-3g28CGA-482r-3wm5-h9vcCGA-49m4-p348-9r52CGA-4j74-vg3g-f9m9CGA-598g-69gp-3xhpCGA-598h-9j2c-pgcwCGA-5cc3-92mr-vwrvCGA-5fwf-hcvc-6p78CGA-5wg2-c35c-v2rmCGA-5wxx-hf8x-x52fCGA-6239-j2xj-cf7mCGA-625c-xh7v-8c63CGA-685x-g4h5-pr9rCGA-6h32-ff62-2hm2CGA-6ppv-j2r2-vqv2CGA-6pxw-24cq-cq74CGA-775v-4849-v3jmCGA-78x9-jj5c-4jpmCGA-7fqx-937v-7g3qCGA-7gfp-98gh-qfmvCGA-7mq6-7v8w-5q56CGA-7r25-mc2v-8pwjCGA-83v6-g4f2-xqh7CGA-84x8-hrj5-wcrmCGA-8qm7-436h-4584CGA-968q-h8p9-xw97CGA-9f2g-hfpj-g3vhCGA-9fx4-grc9-fhwpCGA-9qcj-m8qx-5m76CGA-9qvc-wh82-c6mjCGA-9vrf-36wm-2gp2CGA-c8fm-8qgp-56x7CGA-cc3x-66fr-wc3pCGA-cx7p-q4h3-8jx3CGA-f59w-wq7q-cjq7CGA-fm72-qmxg-jhjmCGA-fv3h-p37x-qpqrCGA-g5w8-whgx-r543CGA-g6vw-f8c6-w68wCGA-gjf2-hw7p-pcxfCGA-h37h-xw6m-3pw5CGA-h4m4-v77m-hwprCGA-h4m6-xc5h-8xhvCGA-h546-hq7j-vfqcCGA-h598-f2r9-7mx7CGA-h896-jxp9-9g2cCGA-hgc6-wv5x-q4h5CGA-hh4f-rqf3-wjqwCGA-hr62-xh8j-6rxrCGA-hr6g-4xxv-x7c5CGA-hrj9-g2px-4qwpCGA-j224-f5cf-8x7pCGA-j662-f329-2j7cCGA-jj6j-xcg7-3f77CGA-jr8r-ccw8-5wrwCGA-mf9w-m5c8-fgrpCGA-mj2q-jpxg-2cjgCGA-p63x-xx97-jx55CGA-p76q-g3px-wqhrCGA-pv6g-w3ff-fq3rCGA-pvr7-8j4f-qj89CGA-pvrr-95c8-r9jmCGA-q7cm-q4mm-hmpgCGA-q9wm-7ppr-8j86CGA-qc69-p3mf-pv23CGA-qj76-xvpj-j523CGA-qprm-gpfm-6q43CGA-qw3j-wmfj-2hxmCGA-r254-hjc7-q74cCGA-r43h-2hpj-4jc8CGA-r4v8-jh93-rcj2CGA-rjfx-7pph-wv69CGA-rmrj-w4cv-69mwCGA-rxqj-mg43-cx34CGA-rxvq-85j9-hhg5CGA-v46f-hq8x-m24gCGA-vfm9-8fmj-gpr8CGA-vpc7-7p28-j9fgCGA-vq45-rpp6-px47CGA-vrqm-w28w-8mr7CGA-w8jh-q75m-v94pCGA-wwjv-h99w-vmgwCGA-x2qq-xh4g-64q5CGA-x5xj-x994-7p29CGA-x6c3-qrmj-7cvxCGA-xc49-pxm6-gv66CGA-xg76-qqp3-354xCGA-xpq5-4qwf-8h35CGA-xvfj-v2jp-hfvj
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 08 Nov 2023, 00:00
Last modified:04 Sept 2024, 15:15

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.56% LOW
1% probability +0.42%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

08 Nov 2023, 00:00
Published
Vulnerability first disclosed
04 Sept 2024, 15:15
Last Modified
Vulnerability information updated

Description

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.56% Percentile: 45%

Techniques & Countermeasures

  • CWE-352Cross-Site Request Forgery (CSRF)

    The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Affected Systems

  • chainguardarangodb-3.11

    < 3.11.14.5-r13

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardopensearch-dashboards-2

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-alerting-dashboards-plugin

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-anomaly-detection-dashboards-plugin

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-config

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-maps

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-notifications

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-observability

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-query-workbench

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-reporting

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-search-relevance

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-dashboards-visualizations

    < 2.11.1-r2

  • chainguardopensearch-dashboards-2-fips

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-alerting-dashboards-plugin

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-anomaly-detection-dashboards-plugin

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-config

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-maps

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-notifications

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-observability

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-query-workbench

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-reporting

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-search-relevance

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-dashboards-visualizations

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-index-management-dashboards-plugin

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-ml-commons-dashboards

    < 2.13.0-r0

  • chainguardopensearch-dashboards-2-fips-security-analytics-dashboards-plugin

    < 2.13.0-r0

Showing first 50 affected entries in server-rendered view.

References (16)